Ask the Expert

How can I redirect the event viewer files?

We are about to implement a client solution wherein each client PC loads an image from an image server on each boot-up. Since all the event viewer and log files are lost when the operating system reloads, we are unable to perform forensic troubleshooting. Is there a way to redirect the event viewer files to another partition or network share?

Requires Free Membership to View

Microsoft's Audit Collection Service (ACS) has been in beta for quite some time now, so your current best bets would be either to create a scheduled job on each workstation that dumps the system logs and copies them to a central location, or else to use a third-party utility for Event Log collection such as DorianSoft's Event Archiver: (

When deciding on a solution, remember that Event Log data is critical information that should not be transmitted or stored in an insecure fashion; be sure that the security of your log data both in transit and in storage is a key factor in your decision-making process.

This was first published in November 2005

There are Comments. Add yours.

TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: